Quantum Security & PQC

Europol Urges Early Action on Quantum Threats to Crypto Wallets and Stored Data

October 6, 2026 – Europol published two reports on October 7, 2026 examining how quantum computers could expose cryptocurrency wallets and decrypt sensitive information collected years earlier. The European Union’s law enforcement agency urged organizations, policymakers and the cryptocurrency industry to begin preparing now.

Europol said the timing of those capabilities remains uncertain but “should not be the main concern” because adapting systems and coordinating security upgrades will take time. The agency called for crypto-agility to be pursued proactively and for a phased transition to post-quantum cryptography, prioritized by how exposed each system and asset is.

Quantum Computing and Cryptocurrencies

The first report, Quantum Computing and Cryptocurrencies – Bridging technical expertise and decision-making, was produced by Europol’s European Cybercrime Centre (EC3). It identified the public-key cryptography that controls wallets and authorizes transactions as the main point of exposure, because a sufficiently powerful quantum computer could derive a private key from an exposed public key.

The report said the hash functions used in proof-of-work mining and in the linking of blocks remain largely resistant to quantum attack, as do those used in proof-of-stake systems. It rejected predictions that quantum computing will end cryptocurrencies and described proactive adaptation as the most likely outcome.

It grouped mitigations into three sets: incremental upgrades such as account abstraction, multi-signature schemes and address rotation; adoption of NIST-standardized post-quantum algorithms; and quantum technologies such as quantum key distribution (QKD), which it said face scalability limits.

The report assigned roles to regulators, blockchain projects, wallet providers and users. It advised users to move funds to quantum-resistant wallets as these become available. Its policy guidelines proposed a working group led by the European Commission, with experts from Europol, ENISA, CERT-EU and the EU’s Anti-Money Laundering Authority (AMLA), and asked policymakers to assess the quantum exposure of central bank digital currencies.

Harvest Now, Decrypt Later

The second report, Harvest Now, Decrypt Later, was developed with Universidad Carlos III de Madrid (UC3M) under EC3’s Advisory Group on Research and Development. It examined harvest now, decrypt later (HNDL) attacks, in which encrypted data is collected now and decrypted once quantum or other cryptanalytic capabilities exist, and based its protocol analysis on a March 2026 UC3M preprint.

The report found that TLS, SSH and OpenPGP-encrypted files are all susceptible, with exposure depending on configuration and key management. Under TLS 1.2 with RSA key transport, obtaining a server’s private key can be enough to decrypt past recorded sessions, while the forward-secret key exchanges in TLS 1.3 and SSH require an attacker to break each recorded session separately, the report said.

It rated the risk as high for governments, citing diplomatic cables, intelligence reports and law enforcement case files, including informant identities. It put companies at medium to high risk and citizens at low to medium risk. The report found no clear evidence that the technique is being exploited systematically at scale and said the resources required make high-value information with lasting sensitivity the most plausible target.

Its recommendations included disabling TLS 1.0 and 1.1, enforcing forward secrecy, limiting data retention, piloting hybrid post-quantum key exchange and, for governments, adopting a national PQC strategy. It noted that OpenSSL and OpenSSH already ship hybrid post-quantum key exchange by default. The report said continued use of TLS 1.0 and 1.1 creates an immediate “Harvest Now, Decrypt Now” risk that requires no quantum computer.

Earlier Europol Work on Quantum Risk

The reports build on Europol’s 2023 report on quantum technologies and law enforcement, a February 2025 call to action from its Quantum Safe Financial Forum and a January 2026 joint report on prioritizing post-quantum migration in financial services. Europol tied the release to its 10th Global Conference on Criminal Finances and Cryptoassets, held September 15–16, 2026 in Luxembourg with the Basel Institute on Governance and the UN Office on Drugs and Crime.

My Analysis

Europol Separates Wallet Forgery From Retrospective Decryption

Europol keeps apart two problems that much quantum coverage blurs. A cryptocurrency wallet faces forgery: whoever derives the private key from an exposed public key can sign a transaction and move the funds. Recorded traffic and stored files face retrospective decryption, which matters only for data that will still be sensitive when decryption becomes feasible. Europol’s cryptocurrency report identifies wallet signing keys as the main exposure and finds the hash functions behind mining largely resistant. The HNDL report points to data that stays sensitive for years as the most plausible target. Its announcement names crypto-agility as the goal and tells readers to act without waiting for a quantum date. I have made the same argument about deadlines: regulators, insurers and clients have already set the dates that drive budgets. A migration takes years whatever the forecast says.

Both reports are written for decision-makers, and they do that job well. The HNDL report’s walk through TLS 1.2, TLS 1.3, SSH and OpenPGP explains forward secrecy under a quantum threat model more clearly than most vendor material I read. A ministry or police force can use its three risk tiers as a starting order. The report’s first managerial recommendation is an inventory of where cryptography is deployed, and I would begin there too.

For data in transit, the report notes that OpenSSL and OpenSSH already ship hybrid post-quantum key exchange by default. Chrome has used the same kind of hybrid since late 2024, and by October 2025 more than half of the human traffic through Cloudflare used it. For many organizations, the remaining work is finding the systems that do not negotiate it. For cryptocurrencies, I find more support for Europol’s call to migrate early in the figures published this year, from Google Quantum AI’s March 2026 resource estimate to Glassnode’s count of about 30% of bitcoin with exposed public keys.

Agency teams usually spend months drafting reports like these and clearing them through internal approval. The newest dated source in the HNDL report is an IETF draft from May 20, 2026. Since then, the IETF has published post-quantum OpenPGP (June), the design for hybrid key exchange in TLS 1.3 (July) and the hybrid ML-KEM groups for TLS 1.3 (August), and GnuPG has added an opt-in mode for the new OpenPGP standard (September). I read the dated details below as a measure of how quickly standards bodies and developers have moved since May.

Neither report moves the timeline to a cryptographically relevant quantum computer (CRQC), since neither contains a new resource estimate or hardware result. Europol has joined the EU institutions telling member states to start now, 12 weeks before the end-2026 milestone in the EU’s post-quantum roadmap.

Hybrid ML-KEM Is the Default in OpenSSH, OpenSSL and Chrome

Europol’s HNDL report recommends hybrid key exchange where full migration is not yet feasible. Its authors note that OpenSSL and OpenSSH ship a hybrid post-quantum and classical key exchange by default, citing OpenSSH 9.0 from April 2022, whose default hybrid used the NTRU Prime scheme sntrup761. For medium-risk organizations, the report lists PQC under long-term resilience, to be explored as it becomes available through vendor solutions. In current releases, the default hybrid uses ML-KEM (formerly CRYSTALS-Kyber).

OpenSSH 10.0 made mlkem768x25519-sha256 its default key agreement on April 9, 2025 (release notes). OpenSSH 10.1, released in October 2025, warns by default when a connection negotiates a key exchange without a post-quantum component, and its developers gave store-now-decrypt-later attacks as the reason. OpenSSL 3.5.0, released on April 8, 2025, offers X25519MLKEM768 in its default TLS key shares. Google switched Chrome’s hybrid from Kyber to ML-KEM in Chrome 131, and in the last week of October 2025 Cloudflare reported that the majority of human-initiated traffic to its network used post-quantum key agreement.

The IETF published the design for hybrid key exchange in TLS 1.3 as RFC 9954 in July 2026 and the hybrid ML-KEM groups, including X25519MLKEM768, as RFC 10024 in August 2026.

Between Chrome and servers on OpenSSL 3.5 or later, and between OpenSSH 10 clients and servers, hybrid key exchange happens without anyone configuring it. Whether an organization benefits depends on what its endpoints negotiate on every hop, including load balancers and TLS-terminating appliances on old firmware, VPN concentrators, Java and embedded stacks, partner links and internal service meshes. Configuration files and vendor documentation are a poor guide to that; teams find the gaps by recording the key-exchange group each connection selects. Hybrid key exchange protects confidentiality, and the certificates that authenticate those connections are a separate migration, which Europol’s report also covers.

Europol’s mitigation chapter puts the inventory first, and I agree with that order. A cryptographic inventory that records negotiated key exchanges shows where an upgrade or a hybrid pilot is needed.

Post-Quantum OpenPGP Has Been an RFC Since June 2026

Europol’s report describes the IETF as finalizing post-quantum support for OpenPGP. That work was published as RFC 9980 in June 2026, with ML-KEM-768 plus X25519 composite encryption and ML-DSA-65 (formerly CRYSTALS-Dilithium) plus Ed25519 composite signatures. RFC 9980 also specifies SLH-DSA (formerly SPHINCS+) as a standalone signature option. It extends RFC 9580, the 2024 crypto refresh, which contains no post-quantum algorithms.

Europol’s authors also point readers to GnuPG builds with post-quantum support. GnuPG’s Kyber composite, available since version 2.5.0 in 2024, follows the LibrePGP specification, and as I wrote when RFC 9980 appeared, messages from the two camps can fail to decrypt across them even when both sides run ML-KEM-768 with X25519. GnuPG 2.5.24, released on September 23, 2026, added an opt-in --allow-9980 mode that processes RFC 9980 data structures, including ML-KEM composite encryption. Its developers recommend that mode only where external policy requires RFC 9980. An organization choosing a tool for encrypted archives it will keep for years should test encryption and decryption between the exact tools, versions and modes it plans to use.

For stored data, Europol’s short-term advice is to rotate keys and re-encrypt older ciphertexts under fresh keys, and its longer-term advice is to move to post-quantum encryption tools. The second step is the one that protects a retained archive against a future quantum computer. Neither step reaches copies an adversary already took, such as PGP-encrypted email that crossed the internet, and those copies are the material HNDL describes.

Storage Costs in Europol’s Report and in the UC3M Preprint

Europol says the HNDL report is based on a March 2026 preprint by Javier Blanco-Romero, Florina Almenares Mendoza, Carlos García Rubio, Celeste Campo and Daniel Díaz Sánchez of UC3M. The authors treat HNDL as an economic problem. At commercial cloud prices of $12.16 to $14.74 per terabyte-year, they estimate that archiving 1% of global encrypted traffic costs about $1.1 billion a year and 10% about $11 billion. They call retaining intercepted traffic “economically trivial” and conclude that the defensive question is what decryption costs. In July I put a year of a large organization’s external traffic, at 1 to 10 terabytes a day, at $5,000 to $70,000 in hard disks.

In its announcement, Europol says HNDL would require significant storage, processing and technical resources, which is why high-value information with lasting sensitivity is the most plausible target. I agree with Europol about the target. On the UC3M numbers, storing the traffic is cheap, and decryption is the expensive step.

With forward secrecy, each recorded TLS 1.3 or SSH session that used a fresh classical key exchange needs its own run of Shor’s algorithm. Google Quantum AI’s March 2026 whitepaper estimates 18 or 23 minutes per 256-bit elliptic-curve key on a superconducting machine with fewer than 500,000 physical qubits at a 0.1% physical error rate, a machine nobody has built. Google’s authors calculate the figures for secp256k1 and apply them to similar elliptic curves. Bitcoin signs with secp256k1, and most TLS and SSH key exchanges use other 256-bit curves.

On those single-key figures, one such machine would recover 60 to 80 session keys a day. The whitepaper also describes reusing quantum state to derive several keys in one run, which would raise that number by an amount it does not estimate. An adversary can afford to record far more than it can decrypt, and will have to choose which sessions to open until such machines become faster and more numerous.

The UC3M authors also rank defenses by who bears the cost. Each SSH rekey runs a fresh Diffie–Hellman exchange, so an attacker needs a separate key recovery for every epoch. TLS 1.3’s KeyUpdate derives new keys from the previous secret and adds no quantum work, which the authors call a critical protocol gap in TLS 1.3 and QUIC. They name rekeying and key-exchange size as the strongest defensive levers available with current infrastructure, because only the attacker has to do the extra quantum work. Europol’s authors make the complementary point that each SSH rekey is no harder to break than the first exchange. An attacker who wants the whole of a long session still has to break every one of them.

The authors also argue that Encrypted Client Hello, which hides the server name, pushes an adversary toward bulk collection. The effect is strongest on shared hosting with encrypted DNS, where an IP address does not reveal the site.

Europol’s finding that there is no clear evidence of HNDL being exploited systematically at scale is carefully worded, and the report adds that past exfiltration of encrypted data from high-value organizations suggests the prerequisites for future decryption may already be in place. An HNDL program in operation would leave the same absence of evidence: a passive tap on a fiber or a submarine cable produces no event inside the victim’s network. Organizations should not read the lack of public cases as evidence that nobody is recording.

“Harvest Now, Decrypt Now” Also Covers RSA Key Transport and Weak Diffie–Hellman

The most useful idea in the report, to my mind, is its label for recorded traffic that needs no quantum computer at all: Harvest Now, Decrypt Now. Europol attaches the label to TLS 1.0 and 1.1. The IETF deprecated both versions in 2021. The best-known attacks on their CBC cipher suites, such as BEAST and Lucky Thirteen, required an attacker who injects or alters traffic during the session (RFC 7457 summarizes them). None of them decrypts a passive recording of a session that used ephemeral elliptic-curve Diffie–Hellman with AES.

Three well-documented configurations allow classical retroactive decryption, and TLS 1.2 still permits the first two:

  • Static RSA key transport, allowed from TLS 1.0 through 1.2 and removed in TLS 1.3. Whoever later obtains the server’s private key, by theft, legal compulsion or cryptanalysis, can decrypt every recorded session that used it.
  • Weak Diffie–Hellman groups. The 2015 Logjam research estimated that a nation-state could break a 1024-bit prime. Breaking the single most common prime used by web servers would have allowed passive eavesdropping on connections to 18% of the top million HTTPS domains, and a second prime covered 66% of VPN servers and 26% of SSH servers in the researchers’ measurements.
  • RC4, prohibited in all TLS versions in 2015 because its keystream biases let an observer recover plaintext that is encrypted many times, such as cookies.

Europol is right to tell organizations to disable TLS 1.0 and 1.1, for the reasons in RFC 8996. Teams applying the Harvest Now, Decrypt Now idea should also look for TLS 1.2 servers that still accept RSA key transport, which are more exposed to later decryption than a TLS 1.0 endpoint that uses ephemeral key exchange. The test is the key exchange and cipher a connection actually negotiates.

Updates and Corrections to the Cryptocurrency Report

Most of EC3’s conclusions about cryptocurrency are sound. Some of the supporting examples are already out of date. A few need correcting:

  • IOTA has used Ed25519 signatures since 2021. The report names IOTA, with QANplatform, as a project that has already implemented post-quantum signatures. IOTA replaced its Winternitz one-time signatures with Ed25519 when it launched its Chrysalis network in April 2021. Its current network accepts Ed25519, ECDSA on secp256k1 and secp256r1, and multisig. Its identity framework added experimental ML-DSA signatures for verifiable credentials in October 2025; transactions still use classical signatures.
  • QANplatform’s mainnet is still pending. QANplatform runs ML-DSA signatures on a private chain and a testnet, and its roadmap gives no date for the public mainnet.
  • XMSS signatures can be about 2.5 KB. The report puts hash-based signatures such as XMSS at about 20 KB, against 72 bytes for ECDSA. An XMSS signature at tree height 10, the default for QRL’s wallets, is 2,500 bytes. Each additional level of the tree adds 32 bytes. Some SLH-DSA parameter sets reach 17 to 30 KB.
  • Bitcoin’s blockchain is about 774 GB. The report compares a quantum cryptocurrency’s storage with Bitcoin’s 300 GB blockchain, a size the chain passed in September 2020. Blockchain.com’s series, which counts block headers and transactions without database indexes, reached 773.6 GB on October 6, 2026.
  • Bitcoin has no fixed 90% miner rule. Activation thresholds are set per deployment. SegWit’s deployment under Bitcoin Improvement Proposal (BIP) 9 required 95% of blocks to signal; it activated in 2017 through BIP 91, which used a separate 80% threshold to activate the existing deployment. Taproot’s Speedy Trial used 90%.
  • Taproot exposes public keys when coins are received. The report says Taproot’s Schnorr signatures offer no quantum resistance. A Taproot (P2TR) output also puts its tweaked public key on-chain when the coins are received, so they are exposed before they are spent. BIP-360’s own comparison lists P2TR as vulnerable. The report’s figure of under 1% of UTXO value in Taproot outputs matches the 0.75% of value that mempool.space measured at block 892,385 in April 2025.
  • QKD protects links, not spends. The executive summary lists quantum key distribution among the mitigations. QKD can protect a link inside a custody system. Spending from a wallet requires a signature that every node can verify, and QKD does not produce one. The report’s own section on quantum technologies concludes that classical post-quantum algorithms are the feasible path.
  • Exposed keys face forgery. The report describes exposed public keys as open to future quantum decryption. In the on-chain attack nothing is decrypted: the attacker derives the private key and forges signatures, the problem I call Trust Now, Forge Later. Of the NIST algorithms the report names, CRYSTALS-Dilithium (now ML-DSA) is the one that applies to spending; the report correctly labels CRYSTALS-Kyber as key encapsulation.
  • The reactive hard fork has a published design. The report says no cryptographic fix exists for wallets whose public keys are already exposed, and it describes a reactive hard fork that would roll the chain back after a confirmed attack and require ZK-STARK validation. Vitalik Buterin set out that approach for Ethereum in his 2024 emergency-fork outline: after the fork, owners of accounts derived from an HD seed prove knowledge of the seed with a STARK, a hash-based zero-knowledge proof. It helps only owners who still hold the seed, and like Europol, I would treat it as a contingency that does not replace migration.

Ethereum’s Proof-of-Stake Consensus Uses Quantum-Vulnerable Signatures

Europol is right that hash functions protect Bitcoin’s proof-of-work and the linking of its blocks, which use SHA-256. Proof-of-stake chains need one addition to that picture. Ethereum’s validators sign blocks and attestations with BLS12-381 signatures, and the chain’s finality rule counts those signatures.

Ethereum.org’s quantum-resistance page says a quantum computer could break BLS, and that Ethereum will replace it with hash-based leanXMSS signatures for validators, with core post-quantum infrastructure targeted for about 2029 in milestones the page describes as planning targets, not guaranteed commitments. The same page says the Ethereum Foundation formed a dedicated post-quantum security team in January 2026.

A key-recovery attacker on a proof-of-stake chain signs blocks and attestations as the validators whose keys it recovers, with voting weight in proportion to their stake, and other validators accept those signatures as genuine. For those chains, consensus security is a signature problem, and the migration has to cover validators as well as wallets. My October 5 piece tracks the status of Ethereum’s validator migration.

Google’s March 2026 Estimate and Bitcoin’s Mempool Window

The report offers address rotation as a defense, in which a wallet uses a new key pair for each transaction and attackers must re-target each time. Europol’s authors note its limit themselves: rotation assumes a quantum computer cannot break a key instantly, a risk they say grows with technological progress. Rotating to output types that commit only to a hash of the key, such as P2WPKH, keeps each public key hidden until its coins are spent. The spend itself still reveals the key while the transaction waits in the mempool.

Google Quantum AI’s whitepaper estimates that a first-generation superconducting CRQC, primed in advance, could recover a secp256k1 key in about 9 minutes on average, against Bitcoin’s 10-minute average block interval, with a success probability slightly less than 41% under idealized assumptions. I covered the estimate in March. On that estimate, address rotation protects unspent coins but not the spend itself, which is the risk Europol’s authors anticipated. Europol concludes, drawing on Pont and colleagues’ analysis of just-in-time attacks, that cryptocurrencies must complete their migration before practical quantum computers exist, and Google’s numbers support that conclusion.

Europol presents its incremental measures, from address rotation to multi-signature schemes and account abstraction, as complements to post-quantum cryptography that do not replace it. Each is only as quantum-resistant as the signature scheme behind it.

For the size of the exposure, Glassnode’s May 2026 analysis counts 6.04 million BTC, 30.2% of issued supply, with a visible public key: 1.92 million because of the script type (early pay-to-public-key, bare multisig and Taproot outputs) and 4.12 million through address reuse and spending patterns, including 1.63 million in exchange-related balances.

Europol advises users to move funds to quantum-resistant wallets as these become available, and none exists yet for Bitcoin. BIP-360, now called Pay-to-Merkle-Root, was merged into the BIPs repository as a draft in February 2026; it removes Taproot’s key-path exposure and adds no post-quantum signature. BIP-361, which would phase out legacy signatures, was merged as a draft in April 2026 and depends on a post-quantum signature BIP that its header still lists as to be determined. Neither is activated. Until Bitcoin adopts quantum-resistant spending rules, holders can stop reusing addresses and keep balances in outputs that reveal only a hash of the key, which reduces long-exposure risk and leaves on-spend risk unchanged. My October 5 analysis covers the migration status of individual chains.

Encrypted Evidence and Seized Cryptocurrency in Police Custody

For Europol’s own readers, the most actionable line in either report is the high-risk rating for law enforcement case files and informant identities. Those records stay sensitive for decades, and a harvester would tap the links that carry them between national forces, Europol and partner agencies. A police IT team can start this month by recording which key exchange each of those links negotiates.

Police forces also hold lawfully obtained encrypted evidence they cannot yet read. Europol’s 2023 report said store-now-decrypt-later “may offer an opportunity for law enforcement to gain later access to encrypted evidence” obtained now, and Europol launched a decryption platform with the European Commission’s Joint Research Centre in December 2020. A future Europol report could take up that side of HNDL: how long forces keep encrypted material they cannot read today, and under what rules they would open it once they can.

Asset-recovery offices also manage seized cryptocurrency. Seized coins are kept in custody wallets, and the US Strategic Bitcoin Reserve is capitalized with BTC forfeited in criminal or civil proceedings. Custody wallets are exposed in the same way as anyone else’s. Europol’s announcement pointed to its September conference, hosted by Luxembourg’s asset-management office. Agencies that hold seized cryptocurrency need migration plans for their custody wallets as well.

What the Reports Change

Europol has joined the European Commission and national cybersecurity agencies in telling organizations to move before a date is known. The EU’s Coordinated Implementation Roadmap expects member states to start the transition, including national strategies, by the end of 2026, and to protect high-risk systems by the end of 2030 (my summary of the roadmap). For a member state that has not started, the roadmap’s milestone for starting the national strategy Europol recommends is 12 weeks away.

If the Commission sets up the working group the cryptocurrency report proposes, with Europol, ENISA, CERT-EU and AMLA, EU supervisors would have one forum for quantum risk in crypto-assets. That group can start from the data published this year: exposure counts such as Glassnode’s, the status of BIP-360 and BIP-361, and Ethereum’s validator roadmap.

Europol’s authors end the HNDL report by telling each organization to run its own quantum threat risk assessment. I would start that assessment with one count: how many of an organization’s connections, archives and wallets already use post-quantum cryptography. For TLS and SSH between current clients and servers, hybrid key exchange is already the default. Security teams still have to find the connections that do not use it.


Disclosure: Steve Vaile, one of BIP-361’s authors, is Consulting Director for EMEA at Applied Quantum, which sells post-quantum migration advisory services. I also advise Project Eleven, which works on post-quantum security for digital assets; no Project Eleven material is cited here.

From the author

Marin Ivezic

I am the Founder of Applied Quantum (AppliedQuantum.com), a research-driven consulting firm empowering organizations to seize quantum opportunities and proactively defend against quantum threats. A former quantum entrepreneur, I’ve previously served as a Fortune Global 500 CISO, CTO, Big 4 partner, and leader at Accenture and IBM. Throughout my career, I’ve specialized in managing emerging tech risks, building and leading innovation labs focused on quantum security, AI security, and cyber-kinetic risks for global corporations, governments, and defense agencies. I regularly share insights on quantum technologies and emerging-tech cybersecurity at PostQuantum.com. I also founded and teach at Quantum Academy (QuantumAcademy.com) which trains and certifies professionals in post-quantum cryptography, quantum computing, networking and sensing.